A high-level execution chain | Image: Volexity
At a Glance
| Attribute | Details |
|---|---|
| Actor or Group | UTA0565 (suspected Chinese state-sponsored espionage group) |
| Activity Type | Spear-phishing, zero-day exploit chaining, website spoofing |
| Targets or Victims | Asian government agencies, think tanks, policy institutes |
| Scale | Targeted espionage operations across Asia and the United States |
| Jurisdiction / Status | Suspected Chinese cyber espionage group; uncharged |
| Source | Volexity Threat Research (supported by Proofpoint findings) |
Executive Summary
A suspected Chinese threat actor launched targeted phishing attacks using zero-day flaws in Google Chrome and Microsoft Windows. Specifically, the attacker directed victims to clone websites that executed exploit code within hidden inline frames. The infection chain secretly installed a custom backdoor named CLEANGULP to control compromised workstations.
What Happened During the Zero-Day Campaign
The campaign began in early September 2026 with targeted spear-phishing messages. First, the attackers sent emails to Asian government bodies. These emails discussed imprisoned Hong Kong activist Chow Hang-tung. Furthermore, another message spoofed the Center for American Progress to target policy researchers.
Each email contained links leading to attacker-controlled spoofed web domains. For example, the hackers cloned the China Digital Times website on a fake domain. Additionally, they mirrored the Center for American Progress portal using a typosquatted web address. Volexity noted, ‘Using real content from legitimate websites as decoy material continues to be an effective way to reduce user suspicion.’
Exploit Chaining and CLEANGULP Deployment
When a visitor opened the clone site, an invisible iframe loaded an exploit configuration file. This configuration delivered chained exploits targeting Chrome vulnerabilities CVE-2026-85046 and CVE-2026-87491. In addition, the kit deployed Windows privilege escalation exploit CVE-2026-85880. Volexity confirmed, ‘This HTML element consists of the same components used in previously analyzed exploitation of Chrome (CVE-2026-85046, CVE-2026-87491) and Windows local privilege escalation exploits (CVE-2026-85880).’
The exploit script downloaded an executable named chrome_cleanup.exe. Next, the script removed the Windows Mark of the Web flag. It then executed the file using Component Object Model interfaces. Consequently, the payload installed the previously unknown CLEANGULP malware into the local application directory. The backdoor creates a scheduled task named MicrosoftIME to guarantee persistence across reboots.
CLEANGULP supports five core commands, including command execution, process listing, file transfers, and beacon object file execution. The malware communicates over HTTP with a typosquatted domain. Furthermore, the malware encrypts communication bodies using AES-256-GCM with a custom Base64 alphabet.
Who Is Behind the Intrusions
Volexity tracks the threat group behind these attacks under the moniker UTA0565. Analysts assess with moderate confidence that the group operates on behalf of Chinese state interests. The operators share operational tooling with two other Chinese espionage clusters identified earlier this month.
Independent research from Proofpoint confirmed that multiple distinct operators use this shared exploit kit. As Volexity observed, ‘This seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese CNE community, where the core kit was likely shared, customized, and weaponized by multiple groups.’ Consequently, shared zero-day development pipelines support several regional attack groups.
Impact and Operational Scale
The UTA0565 zero-day exploits targeted high-level policy analysts and Asian government officials. Threat actors actively used these exploits on September 3 and September 4 before vendors issued patches. Therefore, victims faced total endpoint compromise simply by visiting cloned web pages.
Security researchers also discovered several additional domains registered by the same operators. Censys internet scans revealed fake portals spoofing international news networks and corporate training firms. Furthermore, attackers set up cloned restaurant directories and human resource services. This broad infrastructure suggests plans for wider espionage collection.
How to Stay Protected
Organizations must apply the latest security updates for Google Chrome and Microsoft Windows immediately. Because the attack relies on spear-phishing, email gateways should block incoming messages containing typosquatted domains. Additionally, security teams must inspect internal traffic for abnormal connections to unverified media websites.
Administrators should audit scheduled tasks for suspicious entries pointing to user application directories. Endpoint detection agents should block unapproved executables operating from input method editor folders. Fast patch deployment remains the primary defense against zero-day exploit kits.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!